SlideShare a Scribd company logo
Walt Murray
CEO
Walt Murray President and CEO of ARC Experts is representing
Quality and Compliance Consulting (QCC) services team for Master
Control, Inc. Walt is a globally recognized compliance and risk
consultant, is a quality management and regulatory affairs professional
with more than 32 years of experience working with internationally
recognized, highly regulated companies, including Aventis, Merck etc.
Walt has performed more than 400 1st, 2nd and 3rd-party audits.
Contact Information
walt.murray@arcexperts.com
www.arcexperts.com
linkedin.com/walt.murray
Risk: How Big of a Deal?
ISO 9001:2008 ISO 9001:2015
3 “risk’ mentions 43 “risk” mentions
Overview
A key change in the 2015 revision is to establish a systematic
approach to risk, rather than treating it as a single component of a
quality management system.
• In previous editions of ISO 9001, a clause on preventive action
was separated from the whole. Now risk is considered and
included throughout the standard.
• By taking a risk-based approach, an organization becomes
proactive rather than purely reactive.
ISO 9001:2015 September 23rd (3 years!)
Overview (continued)
New language in the final draft international standard of ISO
9001 focuses on “risk- based thinking,” although it stops short
of actual “risk management.” As a result, the international
community is wrestling with how best to handle risk.
What does ISO 9001:2015 ask for?
Overview (continued)
In ISO 9001:2015 organizations are also asked to “address risks and
opportunities.”
How do we do that?
“Risk Based Thinking”
What is it?
(from ISO/TC 176/SC2)
“Risk-based thinking is something we all do automatically.”
“Risk-based thinking has always been in ISO 9001 – this revision
builds it into the whole management system.”
“Risk-based thinking is already part of the process approach.”
Case Study
Engineering orientation to risk based thinking!
Benefits of “Risk Based Thinking”
Benefit Example
Prioritize Resources Preparation for an
Audit/Inspection, CAPA
prioritization, etc.
Improve Customer Rapport Deal with complaints that
matter, escalate efficiently
serious issues to the proper
channel
Consistency in Products and
Services
Cost of Quality (CoQ) Curve
Objective evaluations Supplier Selection, Audit
Observations, etc.
Moves towards Proactive vs
Reactive
PA versus CA
How to Use Risk Based Thinking?
What is required?
•Identify what the risks and opportunities are in your
organization (hint: it depends on context)
Note: ISO 9001:2015 does not require you to carry out a
full, formal risk assessment
ISO 31000 (Risk management & Principles and
guidelines) is a useful reference (note: it is not
mandated)
“Risks and Opportunities”
Key Concepts:
•Analyze and prioritize the risks and
opportunities in your organization
•what is acceptable?
•what is unacceptable?
•Plan actions to address the risks
•how can I avoid or eliminate the risk?
•how can I mitigate the risk?
•Implement the plan – take action
•Check the effectiveness of the actions
•does it work?
•Learn from experience – continual improvement
Let’s analyze the risks and opportunities
ISO 9001:2015?
Part 1: Where is “Risk” mentioned in
Where is Risk Mentioned in 9001:2015?
Introduction
0.1 General:
“The risks associated with its context and objectives”
0.3 Process approach:
“….with an overall focus on risk based thinking"
0.5 “Risk-based thinking”:
“Risk is the effect of uncertainty on an expected result and the concept of risk-
based thinking has always been implicit in ISO 9001”
0.6 Compatibility with other management system standards:
“Processes for planning and consideration of risks and opportunities”
Where is Risk Mentioned in 9001:2015?
3. Terms and definitions
3.09 Risk:
“effect of uncertainty on an expected result”
Where is Risk Mentioned in 9001:2015?
4 Context of the organization
4.4 Quality management system and its processes:
“the risks and opportunities in accordance with the requirements
of 6.1, and plan and implement the appropriate actions to address
them”
Where is Risk Mentioned in 9001:2015?
5 Leadership
5.1.2 Customer focus:
“the risks and opportunities that can affect conformity of products
and services and the ability to enhance customer satisfaction are
determined and addressed”
Where is Risk Mentioned in 9001:2015?
6 Planning for the quality management system
6.1 Actions to address risks and opportunities:
“When planning for the quality management system, the
organization shall consider the issues referred to in 4.1 and the
requirements referred to in 4.2 and determine the risks and
opportunities that need to be addressed”
Where is Risk Mentioned in 9001:2015?
8 Operation
8.5.5 Post-delivery activities:
“the risks associated with the products and services”
Where is Risk Mentioned in 9001:2015?
9 Performance evaluation
9.3 Management review:
“the effectiveness of actions taken to address risks and
opportunities (see clause 6.1)”
Where is Risk Mentioned in 9001:2015?
APPENDIX
A.4 Risk-based approach:
“Although risks and opportunities have to be determined and addressed, there
is no requirement for formal risk management or a documented risk
management process”
A.7 Organizational knowledge:
“…additional knowledge needs to take account of the organization’s context,
including its size and complexity, the risks and opportunities it needs to
address…”
A.8 Control of externally provided products and services
“The organization is required to take a risk-based approach to determine the
type and extent of controls appropriate to particular external providers and
externally provided products and services.”
ISO 9001:2015
Part 2: Risk Tools for
Risk Tools
What the standard doesn’t require:
Remember: the standard DOES NOT prescribe a methodology or
require a documented process for risk-based thinking.
Ultimately, it is up to an organization to choose a suitable process or
specific methodology to address risk.
Risk Tool Selection
Choose Wisely…
(From ISO 31010):
“it should be justifiable and appropriate to the situation or organization
under consideration;”
“it should provide results in a form which enhances understanding of the
nature of the risk and how it can be treated;”
“it should be capable of use in a manner that is traceable, repeatable and
verifiable.”
Risk Tool Selection (part 2)
Consider:
• the objectives of the study;
• the needs of decision-makers;
• the type and range of risks being analyzed;
• the potential magnitude of the consequences;
• the degree of expertise, human and other resources needed;
• the availability of information and data;
• the need for modification/updating of the risk assessment, and
• any regulatory and contractual requirements.
Risk assessment process
Risk analysisTools and techniques Risk
Identification Consequence Probability Level of risk
Risk
evaluation
See
Annex
Brainstorming SA1)
NA2)
NA NA NA B 01
Structured or semi-structured
interviews
SA NA NA NA NA B 02
Delphi SA NA NA NA NA B 03
Check-lists SA NA NA NA NA B 04
Primary hazard analysis SA NA NA NA NA B 05
Hazard and operability studies
(HAZOP)
SA SA A3) A A B 06
Hazard Analysis and Critical Control
Points (HACCP)
SA SA NA NA SA B 07
Environmental risk assessment SA SA SA SA SA B 08
Structure « What if? » (SWIFT) SA SA SA SA SA B 09
Scenario analysis SA SA A A A B 10
Business impact analysis A SA A A A B 11
Root cause analysis NA SA SA SA SA B 12
Failure mode effect analysis SA SA SA SA SA B 13
Fault tree analysis A NA SA A A B 14
Event tree analysis A SA A A NA B 15
Cause and consequence analysis A SA SA A A B 16
Cause-and-effect analysis SA SA NA NA NA B 17
Layer protection analysis (LOPA) A SA A A NA B 18
Decision tree NA SA SA A A B 19
Human reliability analysis SA SA SA SA A B 20
Bow tie analysis NA A SA SA A B 21
Reliability centred maintenance SA SA SA SA SA B 22
Sneak circuit analysis A NA NA NA NA B 23
Markov analysis A SA NA NA NA B 24
Monte Carlo simulation NA NA NA NA SA B 25
Bayesian statistics and Bayes Nets NA SA NA NA SA B 26
FN curves A SA SA A SA B 27
Risk indices A SA SA A SA B 28
Consequence/probability matrix SA SA SA SA A B 29
Cost/benefit analysis A SA A A A B 30
Multi-criteria decision analysis
(MCDA)
A SA A SA A B 31
1)
Strongly applicable.
2) Not applicable.
3)
Applicable.
Easy: Brainstorming
Brainstorming involves stimulating and
encouraging free-flowing conversation
amongst a group of knowledgeable people to
identify potential failure modes and associated
hazards, risks, criteria for decisions and/or
options for treatment. The term
“brainstorming” is often used very loosely to
mean any type of group discussion. However
true brainstorming involves particular
techniques to try to ensure that people's
imagination is triggered by the thoughts and
statements of others in the group.
Easy: Structured Interviews
In a structured interview, individual
interviewees are asked a set of prepared
questions from a prompting sheet which
encourages the interviewee to view a
situation from a different perspective and
thus identify risks from that perspective.
A semi-structured interview is similar, but
allows more freedom for a conversation
to explore issues which arise.
Points of risk due to:
 lack of criteria or planned execution
 poor critical thinking skills
 allowance for “fudging” aspects between activities
 not knowing the level of risk
November 30, 2016 30
Audit
Team DEC 2016- DEC 2017
Month/Year
Focusareas
Planned
Conducted
Business
Model
Areas/
Function
TopMgmt
MRTeam*
PdtPlanning
QA
QC
Producment
Suppliers
ReceivingQC
Chngecontrol
In-ProcessQC
ProdCC
Label&Pkg
Personnel
Facilities
Maintenance
Comments
(Part 11, 211, 820, etc. items)
4.1 Quality Mgmt System 13-Jan QM/ MR Minutes/
4.2 Documentation 26-Dec Change control; format; Control
5.0 Management Responsibility 26-Dec Agendas; Participation; Actions
6.2 Resources Allocation 26-Dec QP/Job Desc's; Training; Responsibilities
6.3 Infrastructure 13-Jan Maintenance of facility to GMP/Changes/Events
6.4 Work Environment 27-Dec GMP application for hygiene, mfg, security, docs
7.1 Product/Process Planning 13-Feb Quality Plan, QM, Risk in IQA, Suppliers, Testing
7.2 Customer Requirements 13-Mar Review of Customer Specs/MMR development
7.3 Design & Development TBD Done by UAS. Auditing in 1Q 2013 with transfer
7.4 Purchasing 25-Jan Qualification of suppliers
7.5 Provision of Product 18-Dec MMRs to BMRs/review/approval
7.6 Calibration Capability 10-Jan By contract and in the field
8.2.1 M&M Customer 1Q Progress Reviews
8.2.2 Internal Audits 18-Dec Initially by contractor
8.2.3 M&M Processes 18-Dec Desktop for all processes, SOPs,Wis, Protocols
8.2.4 M&M Products 18-Dec BMRs/Logs/Reports, Raw Matl testing, CofAs
8.3 Control of Nonconformity 27-Dec NCR form and records
8.4 Analysis of Data 1Q Use data from NCRs
8.5.1 Continual Improvement 1Q Mgmt Review actions
8.5.2 Corrective Action 27-Dec Records of improvement actions
8.5.3 Preventive Action 28-Dec Records of improvement actions
AUDIT PLAN/SCHEDULE PREPARED BY: (*MR = Management Review)Gopul K Tunga
NOTES:
12/18/2016
Any IAFs generated to showing where improvements are
identified in the process above and timeline
Audit
No. Audit Dates
AUDIT ELEMENT &
DESCRIPTION
ISO 9001: 2000 &
21 CFR Part XXX
Validation Activity for processes
Accomplished with Internal Auditing
Why be concerned?
©2008PathWise,
Inc.QualityEvents
Escalation
PRACTICLE APPROACH FOR RISK (Product/Process/System)
Case Study 2: Eyjafjallajökull
What Risk Tools should be used?
STOP! Do not pass go…
Where’smystuff!?!?!?!?!?!
The cloud of ash from the Icelandic volcano which has
wreaked havoc on passengers and airports across Europe
has also had significant global effects. The International Air
Transport Association estimates that the ash crisis has led to
the cancellation of hundreds of thousands of flights and cost
the world's airlines many billions of dollars. Some airlines
may not recover from the losses incurred.
Risk is all about uncertainty or, more importantly, the effect
of uncertainty on the achievement of objectives. On 15
November 2009, ISO published ISO 31000:2009, Risk
Management – Principles and guidelines, to help industrial,
commercial and public sector organizations to confidently
address such risks.
BOWTIEANALYSIS
Summary
Risk is here: get used to it
•Mentioned 43x in the new update (vs 3x)
•Risk-Based Thinking – it’s everywhere
•It’s more than just risk: it’s opportunities
•Use the correct tool for the job
•And if nothing else:
PS: DON’T RUN ELECTRICITY THROUGH A
POOL
ISO 9001 Training Course
 ISO 9001 Introduction
1 Day Course
 ISO 9001 Foundation
2 Days Course
 ISO 9001 Lead Implementer
5 Days Course
 ISO 9001 Lead Auditor
5 Days Course
Exam and certification fees are included in the training price.
https://www.pecb.com/iso-9001-training-courses| www.pecb.com/events
THANK YOU
?
walt.murray@arcexperts.com
www.arcexperts.com
linkedin.com/walt.murray

More Related Content

What's hot

How to establish strategic approach to ISO 9001:2015
How to establish strategic approach to ISO 9001:2015How to establish strategic approach to ISO 9001:2015
How to establish strategic approach to ISO 9001:2015
PECB
 
PECB Webinar: Risk Management in IT Services
PECB Webinar: Risk Management in IT ServicesPECB Webinar: Risk Management in IT Services
PECB Webinar: Risk Management in IT Services
PECB
 
PECB Webinar: Enterprise Risk Management - Unsuccessful efforts due to lack o...
PECB Webinar: Enterprise Risk Management - Unsuccessful efforts due to lack o...PECB Webinar: Enterprise Risk Management - Unsuccessful efforts due to lack o...
PECB Webinar: Enterprise Risk Management - Unsuccessful efforts due to lack o...
PECB
 
How to align a Robust Materiality Assessment with Corporate Strategy and Target?
How to align a Robust Materiality Assessment with Corporate Strategy and Target?How to align a Robust Materiality Assessment with Corporate Strategy and Target?
How to align a Robust Materiality Assessment with Corporate Strategy and Target?
PECB
 
Busines Continuity And Compliance
Busines Continuity And ComplianceBusines Continuity And Compliance
Busines Continuity And Compliance
salamali
 
Material Unwanted Events - Critical Control Mangement
Material Unwanted Events - Critical Control MangementMaterial Unwanted Events - Critical Control Mangement
Material Unwanted Events - Critical Control Mangement
SAMTRAC International
 
Introduction to Hazardous Material, Worker Health, Housekeeping and Hygiene
Introduction to Hazardous Material, Worker Health, Housekeeping and HygieneIntroduction to Hazardous Material, Worker Health, Housekeeping and Hygiene
Introduction to Hazardous Material, Worker Health, Housekeeping and Hygiene
PECB
 
Iso 31000 risk mgmt white paper lakshy
Iso 31000 risk mgmt white paper lakshyIso 31000 risk mgmt white paper lakshy
Iso 31000 risk mgmt white paper lakshy
Lakshy Management Consultant Pvt Ltd
 
Building a strong BC programme with ISO 22301
Building a strong BC programme with ISO 22301Building a strong BC programme with ISO 22301
Building a strong BC programme with ISO 22301
PECB
 
Control Self Assessment
Control Self AssessmentControl Self Assessment
Control Self Assessment
Manoj Agarwal
 
Risk based thinking
Risk based thinkingRisk based thinking
Risk based thinking
Ramasubramanian S
 
Improving effectiveness of internal auditing
Improving effectiveness of internal auditingImproving effectiveness of internal auditing
Improving effectiveness of internal auditing
PECB
 
Risk Technology Strategy, Selection and Implementation
Risk Technology Strategy, Selection and ImplementationRisk Technology Strategy, Selection and Implementation
Risk Technology Strategy, Selection and Implementation
Risk Management Institution of Australasia
 
Presentation_20110802213554
Presentation_20110802213554Presentation_20110802213554
Presentation_20110802213554
P Karlin Panggalo.SE.MM.Ak.CA.CFA.CCM
 
Leveraging Effective Risk Management and Internal Control for Your Organization
Leveraging Effective Risk Management and Internal Control for Your OrganizationLeveraging Effective Risk Management and Internal Control for Your Organization
Leveraging Effective Risk Management and Internal Control for Your Organization
International Federation of Accountants
 
Internal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality AuditsInternal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality Audits
Nimonik
 
D1 security and risk management v1.62
D1 security and risk management  v1.62D1 security and risk management  v1.62
D1 security and risk management v1.62
AlliedConSapCourses
 
PECB Webinar: The Impact ISO 9001 Revisions Will Have on Your Business and Qu...
PECB Webinar: The Impact ISO 9001 Revisions Will Have on Your Business and Qu...PECB Webinar: The Impact ISO 9001 Revisions Will Have on Your Business and Qu...
PECB Webinar: The Impact ISO 9001 Revisions Will Have on Your Business and Qu...
PECB
 
Integrated Management Systems
Integrated Management SystemsIntegrated Management Systems
Integrated Management Systems
Dennis Arter
 
Coso erm frmwrk
Coso erm frmwrkCoso erm frmwrk
Coso erm frmwrk
Ravinder Kumar Bhan
 

What's hot (20)

How to establish strategic approach to ISO 9001:2015
How to establish strategic approach to ISO 9001:2015How to establish strategic approach to ISO 9001:2015
How to establish strategic approach to ISO 9001:2015
 
PECB Webinar: Risk Management in IT Services
PECB Webinar: Risk Management in IT ServicesPECB Webinar: Risk Management in IT Services
PECB Webinar: Risk Management in IT Services
 
PECB Webinar: Enterprise Risk Management - Unsuccessful efforts due to lack o...
PECB Webinar: Enterprise Risk Management - Unsuccessful efforts due to lack o...PECB Webinar: Enterprise Risk Management - Unsuccessful efforts due to lack o...
PECB Webinar: Enterprise Risk Management - Unsuccessful efforts due to lack o...
 
How to align a Robust Materiality Assessment with Corporate Strategy and Target?
How to align a Robust Materiality Assessment with Corporate Strategy and Target?How to align a Robust Materiality Assessment with Corporate Strategy and Target?
How to align a Robust Materiality Assessment with Corporate Strategy and Target?
 
Busines Continuity And Compliance
Busines Continuity And ComplianceBusines Continuity And Compliance
Busines Continuity And Compliance
 
Material Unwanted Events - Critical Control Mangement
Material Unwanted Events - Critical Control MangementMaterial Unwanted Events - Critical Control Mangement
Material Unwanted Events - Critical Control Mangement
 
Introduction to Hazardous Material, Worker Health, Housekeeping and Hygiene
Introduction to Hazardous Material, Worker Health, Housekeeping and HygieneIntroduction to Hazardous Material, Worker Health, Housekeeping and Hygiene
Introduction to Hazardous Material, Worker Health, Housekeeping and Hygiene
 
Iso 31000 risk mgmt white paper lakshy
Iso 31000 risk mgmt white paper lakshyIso 31000 risk mgmt white paper lakshy
Iso 31000 risk mgmt white paper lakshy
 
Building a strong BC programme with ISO 22301
Building a strong BC programme with ISO 22301Building a strong BC programme with ISO 22301
Building a strong BC programme with ISO 22301
 
Control Self Assessment
Control Self AssessmentControl Self Assessment
Control Self Assessment
 
Risk based thinking
Risk based thinkingRisk based thinking
Risk based thinking
 
Improving effectiveness of internal auditing
Improving effectiveness of internal auditingImproving effectiveness of internal auditing
Improving effectiveness of internal auditing
 
Risk Technology Strategy, Selection and Implementation
Risk Technology Strategy, Selection and ImplementationRisk Technology Strategy, Selection and Implementation
Risk Technology Strategy, Selection and Implementation
 
Presentation_20110802213554
Presentation_20110802213554Presentation_20110802213554
Presentation_20110802213554
 
Leveraging Effective Risk Management and Internal Control for Your Organization
Leveraging Effective Risk Management and Internal Control for Your OrganizationLeveraging Effective Risk Management and Internal Control for Your Organization
Leveraging Effective Risk Management and Internal Control for Your Organization
 
Internal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality AuditsInternal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality Audits
 
D1 security and risk management v1.62
D1 security and risk management  v1.62D1 security and risk management  v1.62
D1 security and risk management v1.62
 
PECB Webinar: The Impact ISO 9001 Revisions Will Have on Your Business and Qu...
PECB Webinar: The Impact ISO 9001 Revisions Will Have on Your Business and Qu...PECB Webinar: The Impact ISO 9001 Revisions Will Have on Your Business and Qu...
PECB Webinar: The Impact ISO 9001 Revisions Will Have on Your Business and Qu...
 
Integrated Management Systems
Integrated Management SystemsIntegrated Management Systems
Integrated Management Systems
 
Coso erm frmwrk
Coso erm frmwrkCoso erm frmwrk
Coso erm frmwrk
 

Viewers also liked

Leveraging Gap Assessments and Internal Audits in ISO 22301
Leveraging Gap Assessments and Internal Audits in ISO 22301Leveraging Gap Assessments and Internal Audits in ISO 22301
Leveraging Gap Assessments and Internal Audits in ISO 22301
PECB
 
How to determine a proper scope selection based on ISO 27001?
How to determine a proper scope selection based on ISO 27001?How to determine a proper scope selection based on ISO 27001?
How to determine a proper scope selection based on ISO 27001?
PECB
 
How to minimize threats in your information system using network segregation?
How to minimize threats in your information system using network segregation? How to minimize threats in your information system using network segregation?
How to minimize threats in your information system using network segregation?
PECB
 
The influence of Deming's 14 points to ISO 9001:2015
The influence of Deming's 14 points to ISO 9001:2015The influence of Deming's 14 points to ISO 9001:2015
The influence of Deming's 14 points to ISO 9001:2015
PECB
 
Verification Planning of Food Safety System
Verification Planning of Food Safety SystemVerification Planning of Food Safety System
Verification Planning of Food Safety System
PECB
 
Risk assessment techniques a critical success factor
Risk assessment techniques a critical success factorRisk assessment techniques a critical success factor
Risk assessment techniques a critical success factor
PECB
 
How Climate Change is shaping the Future of Business?
How Climate Change is shaping the Future of Business?How Climate Change is shaping the Future of Business?
How Climate Change is shaping the Future of Business?
PECB
 
ISO 37001 Implementation - The Key to Protecting Your Company’s Reputation
ISO 37001 Implementation - The Key to Protecting Your Company’s ReputationISO 37001 Implementation - The Key to Protecting Your Company’s Reputation
ISO 37001 Implementation - The Key to Protecting Your Company’s Reputation
PECB
 
Corporate Social Responsibility: Balancing the Risks and Rewards
Corporate Social Responsibility: Balancing the Risks and RewardsCorporate Social Responsibility: Balancing the Risks and Rewards
Corporate Social Responsibility: Balancing the Risks and Rewards
PECB
 
We've been hacked! Now, what's the BCP?
We've been hacked! Now, what's the BCP?We've been hacked! Now, what's the BCP?
We've been hacked! Now, what's the BCP?
PECB
 
ISO 50001 – Why EnMS is important for organizations?
ISO 50001 – Why EnMS is important for organizations?ISO 50001 – Why EnMS is important for organizations?
ISO 50001 – Why EnMS is important for organizations?
PECB
 
Integración entre la ISO 27001 y la certificación en continuidad de negocio I...
Integración entre la ISO 27001 y la certificación en continuidad de negocio I...Integración entre la ISO 27001 y la certificación en continuidad de negocio I...
Integración entre la ISO 27001 y la certificación en continuidad de negocio I...
PECB
 
How to Establish a Culture of Safety Excellence
How to Establish a Culture of Safety ExcellenceHow to Establish a Culture of Safety Excellence
How to Establish a Culture of Safety Excellence
PECB
 
Soluciones para la administración de Riesgos
Soluciones para la administración de RiesgosSoluciones para la administración de Riesgos
Soluciones para la administración de Riesgos
PECB
 
6 Pitfalls when Implementing Enterprise Risk Management
6 Pitfalls when Implementing Enterprise Risk Management6 Pitfalls when Implementing Enterprise Risk Management
6 Pitfalls when Implementing Enterprise Risk Management
PECB
 
7 Key Problems to Avoid in ISO 27001 Implementation
7 Key Problems to Avoid in ISO 27001 Implementation7 Key Problems to Avoid in ISO 27001 Implementation
7 Key Problems to Avoid in ISO 27001 Implementation
PECB
 

Viewers also liked (16)

Leveraging Gap Assessments and Internal Audits in ISO 22301
Leveraging Gap Assessments and Internal Audits in ISO 22301Leveraging Gap Assessments and Internal Audits in ISO 22301
Leveraging Gap Assessments and Internal Audits in ISO 22301
 
How to determine a proper scope selection based on ISO 27001?
How to determine a proper scope selection based on ISO 27001?How to determine a proper scope selection based on ISO 27001?
How to determine a proper scope selection based on ISO 27001?
 
How to minimize threats in your information system using network segregation?
How to minimize threats in your information system using network segregation? How to minimize threats in your information system using network segregation?
How to minimize threats in your information system using network segregation?
 
The influence of Deming's 14 points to ISO 9001:2015
The influence of Deming's 14 points to ISO 9001:2015The influence of Deming's 14 points to ISO 9001:2015
The influence of Deming's 14 points to ISO 9001:2015
 
Verification Planning of Food Safety System
Verification Planning of Food Safety SystemVerification Planning of Food Safety System
Verification Planning of Food Safety System
 
Risk assessment techniques a critical success factor
Risk assessment techniques a critical success factorRisk assessment techniques a critical success factor
Risk assessment techniques a critical success factor
 
How Climate Change is shaping the Future of Business?
How Climate Change is shaping the Future of Business?How Climate Change is shaping the Future of Business?
How Climate Change is shaping the Future of Business?
 
ISO 37001 Implementation - The Key to Protecting Your Company’s Reputation
ISO 37001 Implementation - The Key to Protecting Your Company’s ReputationISO 37001 Implementation - The Key to Protecting Your Company’s Reputation
ISO 37001 Implementation - The Key to Protecting Your Company’s Reputation
 
Corporate Social Responsibility: Balancing the Risks and Rewards
Corporate Social Responsibility: Balancing the Risks and RewardsCorporate Social Responsibility: Balancing the Risks and Rewards
Corporate Social Responsibility: Balancing the Risks and Rewards
 
We've been hacked! Now, what's the BCP?
We've been hacked! Now, what's the BCP?We've been hacked! Now, what's the BCP?
We've been hacked! Now, what's the BCP?
 
ISO 50001 – Why EnMS is important for organizations?
ISO 50001 – Why EnMS is important for organizations?ISO 50001 – Why EnMS is important for organizations?
ISO 50001 – Why EnMS is important for organizations?
 
Integración entre la ISO 27001 y la certificación en continuidad de negocio I...
Integración entre la ISO 27001 y la certificación en continuidad de negocio I...Integración entre la ISO 27001 y la certificación en continuidad de negocio I...
Integración entre la ISO 27001 y la certificación en continuidad de negocio I...
 
How to Establish a Culture of Safety Excellence
How to Establish a Culture of Safety ExcellenceHow to Establish a Culture of Safety Excellence
How to Establish a Culture of Safety Excellence
 
Soluciones para la administración de Riesgos
Soluciones para la administración de RiesgosSoluciones para la administración de Riesgos
Soluciones para la administración de Riesgos
 
6 Pitfalls when Implementing Enterprise Risk Management
6 Pitfalls when Implementing Enterprise Risk Management6 Pitfalls when Implementing Enterprise Risk Management
6 Pitfalls when Implementing Enterprise Risk Management
 
7 Key Problems to Avoid in ISO 27001 Implementation
7 Key Problems to Avoid in ISO 27001 Implementation7 Key Problems to Avoid in ISO 27001 Implementation
7 Key Problems to Avoid in ISO 27001 Implementation
 

Similar to Building Practical Risk Application into your QMS

ISO 9001-2015: New Risk Requirements
ISO 9001-2015: New Risk RequirementsISO 9001-2015: New Risk Requirements
ISO 9001-2015: New Risk Requirements
MasterControl
 
Topic 1 - Risk Auditing 1-17.pdf
Topic 1 - Risk Auditing 1-17.pdfTopic 1 - Risk Auditing 1-17.pdf
Topic 1 - Risk Auditing 1-17.pdf
Javier138365
 
Lean Six Sigma Overview (print version)
Lean Six Sigma Overview (print version)Lean Six Sigma Overview (print version)
Lean Six Sigma Overview (print version)
Corey Campbell
 
WHATs NEW IN RISK ASSESSMENT
WHATs NEW IN RISK ASSESSMENTWHATs NEW IN RISK ASSESSMENT
WHATs NEW IN RISK ASSESSMENT
Fred Travis
 
Lean Six Sigma Overview (presentation version)
Lean Six Sigma Overview (presentation version)Lean Six Sigma Overview (presentation version)
Lean Six Sigma Overview (presentation version)
Corey Campbell
 
Model Risk Management: Using an infinitely scalable stress testing platform f...
Model Risk Management: Using an infinitely scalable stress testing platform f...Model Risk Management: Using an infinitely scalable stress testing platform f...
Model Risk Management: Using an infinitely scalable stress testing platform f...
QuantUniversity
 
module_1.pptx
module_1.pptxmodule_1.pptx
module_1.pptx
ssuser432862
 
ISO 9001_2015 Overview Presentation_Hawkeye
ISO 9001_2015 Overview Presentation_HawkeyeISO 9001_2015 Overview Presentation_Hawkeye
ISO 9001_2015 Overview Presentation_Hawkeye
Katie Freeman
 
ISO 31000.pdf
ISO 31000.pdfISO 31000.pdf
ISO 31000.pdf
ssuser840a78
 
A brief Introduction to ISO 9001 2015-Quality Management System
A brief Introduction to ISO 9001 2015-Quality Management SystemA brief Introduction to ISO 9001 2015-Quality Management System
A brief Introduction to ISO 9001 2015-Quality Management System
SARWAR SALAM
 
A Framework Driven Approach to Model Risk Management (www.dataanalyticsfinanc...
A Framework Driven Approach to Model Risk Management (www.dataanalyticsfinanc...A Framework Driven Approach to Model Risk Management (www.dataanalyticsfinanc...
A Framework Driven Approach to Model Risk Management (www.dataanalyticsfinanc...
QuantUniversity
 
Everything you need to know about Risk Management
Everything you need to know about Risk ManagementEverything you need to know about Risk Management
Everything you need to know about Risk Management
ITM Platform
 
FitchLearning QuantUniversity Model Risk Presentation
FitchLearning QuantUniversity Model Risk PresentationFitchLearning QuantUniversity Model Risk Presentation
FitchLearning QuantUniversity Model Risk Presentation
QuantUniversity
 
White paper model risk sept 2011
White paper model risk sept 2011White paper model risk sept 2011
White paper model risk sept 2011
Bank Risk Advisors
 
QMS Risk Workshop.pptx
QMS Risk Workshop.pptxQMS Risk Workshop.pptx
QMS Risk Workshop.pptx
SITTIEBADRIADATUDACU1
 
ISO-9001-2015-training.pptx
ISO-9001-2015-training.pptxISO-9001-2015-training.pptx
ISO-9001-2015-training.pptx
WilfredoMina1
 
Iso 9001-2015-training
Iso 9001-2015-trainingIso 9001-2015-training
Iso 9001-2015-training
JPPaner
 
Iso 9001-2015-training
Iso 9001-2015-trainingIso 9001-2015-training
Iso 9001-2015-training
Umesh Hajare
 
A Sustainable Supply Chain: 4 Things to Tell Management
A Sustainable Supply Chain: 4 Things to Tell ManagementA Sustainable Supply Chain: 4 Things to Tell Management
A Sustainable Supply Chain: 4 Things to Tell Management
John E Griggs, Ph.D.
 
Enterprise 360 degree risk management
Enterprise 360 degree risk managementEnterprise 360 degree risk management
Enterprise 360 degree risk management
Infosys
 

Similar to Building Practical Risk Application into your QMS (20)

ISO 9001-2015: New Risk Requirements
ISO 9001-2015: New Risk RequirementsISO 9001-2015: New Risk Requirements
ISO 9001-2015: New Risk Requirements
 
Topic 1 - Risk Auditing 1-17.pdf
Topic 1 - Risk Auditing 1-17.pdfTopic 1 - Risk Auditing 1-17.pdf
Topic 1 - Risk Auditing 1-17.pdf
 
Lean Six Sigma Overview (print version)
Lean Six Sigma Overview (print version)Lean Six Sigma Overview (print version)
Lean Six Sigma Overview (print version)
 
WHATs NEW IN RISK ASSESSMENT
WHATs NEW IN RISK ASSESSMENTWHATs NEW IN RISK ASSESSMENT
WHATs NEW IN RISK ASSESSMENT
 
Lean Six Sigma Overview (presentation version)
Lean Six Sigma Overview (presentation version)Lean Six Sigma Overview (presentation version)
Lean Six Sigma Overview (presentation version)
 
Model Risk Management: Using an infinitely scalable stress testing platform f...
Model Risk Management: Using an infinitely scalable stress testing platform f...Model Risk Management: Using an infinitely scalable stress testing platform f...
Model Risk Management: Using an infinitely scalable stress testing platform f...
 
module_1.pptx
module_1.pptxmodule_1.pptx
module_1.pptx
 
ISO 9001_2015 Overview Presentation_Hawkeye
ISO 9001_2015 Overview Presentation_HawkeyeISO 9001_2015 Overview Presentation_Hawkeye
ISO 9001_2015 Overview Presentation_Hawkeye
 
ISO 31000.pdf
ISO 31000.pdfISO 31000.pdf
ISO 31000.pdf
 
A brief Introduction to ISO 9001 2015-Quality Management System
A brief Introduction to ISO 9001 2015-Quality Management SystemA brief Introduction to ISO 9001 2015-Quality Management System
A brief Introduction to ISO 9001 2015-Quality Management System
 
A Framework Driven Approach to Model Risk Management (www.dataanalyticsfinanc...
A Framework Driven Approach to Model Risk Management (www.dataanalyticsfinanc...A Framework Driven Approach to Model Risk Management (www.dataanalyticsfinanc...
A Framework Driven Approach to Model Risk Management (www.dataanalyticsfinanc...
 
Everything you need to know about Risk Management
Everything you need to know about Risk ManagementEverything you need to know about Risk Management
Everything you need to know about Risk Management
 
FitchLearning QuantUniversity Model Risk Presentation
FitchLearning QuantUniversity Model Risk PresentationFitchLearning QuantUniversity Model Risk Presentation
FitchLearning QuantUniversity Model Risk Presentation
 
White paper model risk sept 2011
White paper model risk sept 2011White paper model risk sept 2011
White paper model risk sept 2011
 
QMS Risk Workshop.pptx
QMS Risk Workshop.pptxQMS Risk Workshop.pptx
QMS Risk Workshop.pptx
 
ISO-9001-2015-training.pptx
ISO-9001-2015-training.pptxISO-9001-2015-training.pptx
ISO-9001-2015-training.pptx
 
Iso 9001-2015-training
Iso 9001-2015-trainingIso 9001-2015-training
Iso 9001-2015-training
 
Iso 9001-2015-training
Iso 9001-2015-trainingIso 9001-2015-training
Iso 9001-2015-training
 
A Sustainable Supply Chain: 4 Things to Tell Management
A Sustainable Supply Chain: 4 Things to Tell ManagementA Sustainable Supply Chain: 4 Things to Tell Management
A Sustainable Supply Chain: 4 Things to Tell Management
 
Enterprise 360 degree risk management
Enterprise 360 degree risk managementEnterprise 360 degree risk management
Enterprise 360 degree risk management
 

More from PECB

ISO/IEC 27001, ISO/IEC 42001, and GDPR: Best Practices for Implementation and...
ISO/IEC 27001, ISO/IEC 42001, and GDPR: Best Practices for Implementation and...ISO/IEC 27001, ISO/IEC 42001, and GDPR: Best Practices for Implementation and...
ISO/IEC 27001, ISO/IEC 42001, and GDPR: Best Practices for Implementation and...
PECB
 
Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global Impact
PECB
 
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
PECB
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
PECB
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
PECB
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
PECB
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
PECB
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
PECB
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
PECB
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
PECB
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
PECB
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
PECB
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
PECB
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC
PECB
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
PECB
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
PECB
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA
PECB
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
PECB
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptx
PECB
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
PECB
 

More from PECB (20)

ISO/IEC 27001, ISO/IEC 42001, and GDPR: Best Practices for Implementation and...
ISO/IEC 27001, ISO/IEC 42001, and GDPR: Best Practices for Implementation and...ISO/IEC 27001, ISO/IEC 42001, and GDPR: Best Practices for Implementation and...
ISO/IEC 27001, ISO/IEC 42001, and GDPR: Best Practices for Implementation and...
 
Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global Impact
 
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptx
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
 

Recently uploaded

C1 Rubenstein AP HuG xxxxxxxxxxxxxx.pptx
C1 Rubenstein AP HuG xxxxxxxxxxxxxx.pptxC1 Rubenstein AP HuG xxxxxxxxxxxxxx.pptx
C1 Rubenstein AP HuG xxxxxxxxxxxxxx.pptx
mulvey2
 
Traditional Musical Instruments of Arunachal Pradesh and Uttar Pradesh - RAYH...
Traditional Musical Instruments of Arunachal Pradesh and Uttar Pradesh - RAYH...Traditional Musical Instruments of Arunachal Pradesh and Uttar Pradesh - RAYH...
Traditional Musical Instruments of Arunachal Pradesh and Uttar Pradesh - RAYH...
imrankhan141184
 
spot a liar (Haiqa 146).pptx Technical writhing and presentation skills
spot a liar (Haiqa 146).pptx Technical writhing and presentation skillsspot a liar (Haiqa 146).pptx Technical writhing and presentation skills
spot a liar (Haiqa 146).pptx Technical writhing and presentation skills
haiqairshad
 
Mule event processing models | MuleSoft Mysore Meetup #47
Mule event processing models | MuleSoft Mysore Meetup #47Mule event processing models | MuleSoft Mysore Meetup #47
Mule event processing models | MuleSoft Mysore Meetup #47
MysoreMuleSoftMeetup
 
How to deliver Powerpoint Presentations.pptx
How to deliver Powerpoint  Presentations.pptxHow to deliver Powerpoint  Presentations.pptx
How to deliver Powerpoint Presentations.pptx
HajraNaeem15
 
Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"
Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"
Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"
National Information Standards Organization (NISO)
 
مصحف القراءات العشر أعد أحرف الخلاف سمير بسيوني.pdf
مصحف القراءات العشر   أعد أحرف الخلاف سمير بسيوني.pdfمصحف القراءات العشر   أعد أحرف الخلاف سمير بسيوني.pdf
مصحف القراءات العشر أعد أحرف الخلاف سمير بسيوني.pdf
سمير بسيوني
 
LAND USE LAND COVER AND NDVI OF MIRZAPUR DISTRICT, UP
LAND USE LAND COVER AND NDVI OF MIRZAPUR DISTRICT, UPLAND USE LAND COVER AND NDVI OF MIRZAPUR DISTRICT, UP
LAND USE LAND COVER AND NDVI OF MIRZAPUR DISTRICT, UP
RAHUL
 
NEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptx
NEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptxNEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptx
NEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptx
iammrhaywood
 
UGC NET Exam Paper 1- Unit 1:Teaching Aptitude
UGC NET Exam Paper 1- Unit 1:Teaching AptitudeUGC NET Exam Paper 1- Unit 1:Teaching Aptitude
UGC NET Exam Paper 1- Unit 1:Teaching Aptitude
S. Raj Kumar
 
What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...
What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...
What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...
GeorgeMilliken2
 
Pharmaceutics Pharmaceuticals best of brub
Pharmaceutics Pharmaceuticals best of brubPharmaceutics Pharmaceuticals best of brub
Pharmaceutics Pharmaceuticals best of brub
danielkiash986
 
BBR 2024 Summer Sessions Interview Training
BBR  2024 Summer Sessions Interview TrainingBBR  2024 Summer Sessions Interview Training
BBR 2024 Summer Sessions Interview Training
Katrina Pritchard
 
How to Make a Field Mandatory in Odoo 17
How to Make a Field Mandatory in Odoo 17How to Make a Field Mandatory in Odoo 17
How to Make a Field Mandatory in Odoo 17
Celine George
 
Lifelines of National Economy chapter for Class 10 STUDY MATERIAL PDF
Lifelines of National Economy chapter for Class 10 STUDY MATERIAL PDFLifelines of National Economy chapter for Class 10 STUDY MATERIAL PDF
Lifelines of National Economy chapter for Class 10 STUDY MATERIAL PDF
Vivekanand Anglo Vedic Academy
 
Philippine Edukasyong Pantahanan at Pangkabuhayan (EPP) Curriculum
Philippine Edukasyong Pantahanan at Pangkabuhayan (EPP) CurriculumPhilippine Edukasyong Pantahanan at Pangkabuhayan (EPP) Curriculum
Philippine Edukasyong Pantahanan at Pangkabuhayan (EPP) Curriculum
MJDuyan
 
Nutrition Inc FY 2024, 4 - Hour Training
Nutrition Inc FY 2024, 4 - Hour TrainingNutrition Inc FY 2024, 4 - Hour Training
Nutrition Inc FY 2024, 4 - Hour Training
melliereed
 
Wound healing PPT
Wound healing PPTWound healing PPT
Wound healing PPT
Jyoti Chand
 
Benner "Expanding Pathways to Publishing Careers"
Benner "Expanding Pathways to Publishing Careers"Benner "Expanding Pathways to Publishing Careers"
Benner "Expanding Pathways to Publishing Careers"
National Information Standards Organization (NISO)
 
The History of Stoke Newington Street Names
The History of Stoke Newington Street NamesThe History of Stoke Newington Street Names
The History of Stoke Newington Street Names
History of Stoke Newington
 

Recently uploaded (20)

C1 Rubenstein AP HuG xxxxxxxxxxxxxx.pptx
C1 Rubenstein AP HuG xxxxxxxxxxxxxx.pptxC1 Rubenstein AP HuG xxxxxxxxxxxxxx.pptx
C1 Rubenstein AP HuG xxxxxxxxxxxxxx.pptx
 
Traditional Musical Instruments of Arunachal Pradesh and Uttar Pradesh - RAYH...
Traditional Musical Instruments of Arunachal Pradesh and Uttar Pradesh - RAYH...Traditional Musical Instruments of Arunachal Pradesh and Uttar Pradesh - RAYH...
Traditional Musical Instruments of Arunachal Pradesh and Uttar Pradesh - RAYH...
 
spot a liar (Haiqa 146).pptx Technical writhing and presentation skills
spot a liar (Haiqa 146).pptx Technical writhing and presentation skillsspot a liar (Haiqa 146).pptx Technical writhing and presentation skills
spot a liar (Haiqa 146).pptx Technical writhing and presentation skills
 
Mule event processing models | MuleSoft Mysore Meetup #47
Mule event processing models | MuleSoft Mysore Meetup #47Mule event processing models | MuleSoft Mysore Meetup #47
Mule event processing models | MuleSoft Mysore Meetup #47
 
How to deliver Powerpoint Presentations.pptx
How to deliver Powerpoint  Presentations.pptxHow to deliver Powerpoint  Presentations.pptx
How to deliver Powerpoint Presentations.pptx
 
Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"
Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"
Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"
 
مصحف القراءات العشر أعد أحرف الخلاف سمير بسيوني.pdf
مصحف القراءات العشر   أعد أحرف الخلاف سمير بسيوني.pdfمصحف القراءات العشر   أعد أحرف الخلاف سمير بسيوني.pdf
مصحف القراءات العشر أعد أحرف الخلاف سمير بسيوني.pdf
 
LAND USE LAND COVER AND NDVI OF MIRZAPUR DISTRICT, UP
LAND USE LAND COVER AND NDVI OF MIRZAPUR DISTRICT, UPLAND USE LAND COVER AND NDVI OF MIRZAPUR DISTRICT, UP
LAND USE LAND COVER AND NDVI OF MIRZAPUR DISTRICT, UP
 
NEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptx
NEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptxNEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptx
NEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptx
 
UGC NET Exam Paper 1- Unit 1:Teaching Aptitude
UGC NET Exam Paper 1- Unit 1:Teaching AptitudeUGC NET Exam Paper 1- Unit 1:Teaching Aptitude
UGC NET Exam Paper 1- Unit 1:Teaching Aptitude
 
What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...
What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...
What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...
 
Pharmaceutics Pharmaceuticals best of brub
Pharmaceutics Pharmaceuticals best of brubPharmaceutics Pharmaceuticals best of brub
Pharmaceutics Pharmaceuticals best of brub
 
BBR 2024 Summer Sessions Interview Training
BBR  2024 Summer Sessions Interview TrainingBBR  2024 Summer Sessions Interview Training
BBR 2024 Summer Sessions Interview Training
 
How to Make a Field Mandatory in Odoo 17
How to Make a Field Mandatory in Odoo 17How to Make a Field Mandatory in Odoo 17
How to Make a Field Mandatory in Odoo 17
 
Lifelines of National Economy chapter for Class 10 STUDY MATERIAL PDF
Lifelines of National Economy chapter for Class 10 STUDY MATERIAL PDFLifelines of National Economy chapter for Class 10 STUDY MATERIAL PDF
Lifelines of National Economy chapter for Class 10 STUDY MATERIAL PDF
 
Philippine Edukasyong Pantahanan at Pangkabuhayan (EPP) Curriculum
Philippine Edukasyong Pantahanan at Pangkabuhayan (EPP) CurriculumPhilippine Edukasyong Pantahanan at Pangkabuhayan (EPP) Curriculum
Philippine Edukasyong Pantahanan at Pangkabuhayan (EPP) Curriculum
 
Nutrition Inc FY 2024, 4 - Hour Training
Nutrition Inc FY 2024, 4 - Hour TrainingNutrition Inc FY 2024, 4 - Hour Training
Nutrition Inc FY 2024, 4 - Hour Training
 
Wound healing PPT
Wound healing PPTWound healing PPT
Wound healing PPT
 
Benner "Expanding Pathways to Publishing Careers"
Benner "Expanding Pathways to Publishing Careers"Benner "Expanding Pathways to Publishing Careers"
Benner "Expanding Pathways to Publishing Careers"
 
The History of Stoke Newington Street Names
The History of Stoke Newington Street NamesThe History of Stoke Newington Street Names
The History of Stoke Newington Street Names
 

Building Practical Risk Application into your QMS

  • 1.
  • 2. Walt Murray CEO Walt Murray President and CEO of ARC Experts is representing Quality and Compliance Consulting (QCC) services team for Master Control, Inc. Walt is a globally recognized compliance and risk consultant, is a quality management and regulatory affairs professional with more than 32 years of experience working with internationally recognized, highly regulated companies, including Aventis, Merck etc. Walt has performed more than 400 1st, 2nd and 3rd-party audits. Contact Information walt.murray@arcexperts.com www.arcexperts.com linkedin.com/walt.murray
  • 3. Risk: How Big of a Deal? ISO 9001:2008 ISO 9001:2015 3 “risk’ mentions 43 “risk” mentions
  • 4. Overview A key change in the 2015 revision is to establish a systematic approach to risk, rather than treating it as a single component of a quality management system. • In previous editions of ISO 9001, a clause on preventive action was separated from the whole. Now risk is considered and included throughout the standard. • By taking a risk-based approach, an organization becomes proactive rather than purely reactive. ISO 9001:2015 September 23rd (3 years!)
  • 5. Overview (continued) New language in the final draft international standard of ISO 9001 focuses on “risk- based thinking,” although it stops short of actual “risk management.” As a result, the international community is wrestling with how best to handle risk. What does ISO 9001:2015 ask for?
  • 6. Overview (continued) In ISO 9001:2015 organizations are also asked to “address risks and opportunities.” How do we do that?
  • 7. “Risk Based Thinking” What is it? (from ISO/TC 176/SC2) “Risk-based thinking is something we all do automatically.” “Risk-based thinking has always been in ISO 9001 – this revision builds it into the whole management system.” “Risk-based thinking is already part of the process approach.”
  • 8. Case Study Engineering orientation to risk based thinking!
  • 9. Benefits of “Risk Based Thinking” Benefit Example Prioritize Resources Preparation for an Audit/Inspection, CAPA prioritization, etc. Improve Customer Rapport Deal with complaints that matter, escalate efficiently serious issues to the proper channel Consistency in Products and Services Cost of Quality (CoQ) Curve Objective evaluations Supplier Selection, Audit Observations, etc. Moves towards Proactive vs Reactive PA versus CA
  • 10. How to Use Risk Based Thinking? What is required? •Identify what the risks and opportunities are in your organization (hint: it depends on context) Note: ISO 9001:2015 does not require you to carry out a full, formal risk assessment ISO 31000 (Risk management & Principles and guidelines) is a useful reference (note: it is not mandated)
  • 11. “Risks and Opportunities” Key Concepts: •Analyze and prioritize the risks and opportunities in your organization •what is acceptable? •what is unacceptable? •Plan actions to address the risks •how can I avoid or eliminate the risk? •how can I mitigate the risk? •Implement the plan – take action •Check the effectiveness of the actions •does it work? •Learn from experience – continual improvement
  • 12. Let’s analyze the risks and opportunities
  • 13. ISO 9001:2015? Part 1: Where is “Risk” mentioned in
  • 14. Where is Risk Mentioned in 9001:2015? Introduction 0.1 General: “The risks associated with its context and objectives” 0.3 Process approach: “….with an overall focus on risk based thinking" 0.5 “Risk-based thinking”: “Risk is the effect of uncertainty on an expected result and the concept of risk- based thinking has always been implicit in ISO 9001” 0.6 Compatibility with other management system standards: “Processes for planning and consideration of risks and opportunities”
  • 15. Where is Risk Mentioned in 9001:2015? 3. Terms and definitions 3.09 Risk: “effect of uncertainty on an expected result”
  • 16. Where is Risk Mentioned in 9001:2015? 4 Context of the organization 4.4 Quality management system and its processes: “the risks and opportunities in accordance with the requirements of 6.1, and plan and implement the appropriate actions to address them”
  • 17. Where is Risk Mentioned in 9001:2015? 5 Leadership 5.1.2 Customer focus: “the risks and opportunities that can affect conformity of products and services and the ability to enhance customer satisfaction are determined and addressed”
  • 18. Where is Risk Mentioned in 9001:2015? 6 Planning for the quality management system 6.1 Actions to address risks and opportunities: “When planning for the quality management system, the organization shall consider the issues referred to in 4.1 and the requirements referred to in 4.2 and determine the risks and opportunities that need to be addressed”
  • 19. Where is Risk Mentioned in 9001:2015? 8 Operation 8.5.5 Post-delivery activities: “the risks associated with the products and services”
  • 20. Where is Risk Mentioned in 9001:2015? 9 Performance evaluation 9.3 Management review: “the effectiveness of actions taken to address risks and opportunities (see clause 6.1)”
  • 21. Where is Risk Mentioned in 9001:2015? APPENDIX A.4 Risk-based approach: “Although risks and opportunities have to be determined and addressed, there is no requirement for formal risk management or a documented risk management process” A.7 Organizational knowledge: “…additional knowledge needs to take account of the organization’s context, including its size and complexity, the risks and opportunities it needs to address…” A.8 Control of externally provided products and services “The organization is required to take a risk-based approach to determine the type and extent of controls appropriate to particular external providers and externally provided products and services.”
  • 22. ISO 9001:2015 Part 2: Risk Tools for
  • 23. Risk Tools What the standard doesn’t require: Remember: the standard DOES NOT prescribe a methodology or require a documented process for risk-based thinking. Ultimately, it is up to an organization to choose a suitable process or specific methodology to address risk.
  • 24. Risk Tool Selection Choose Wisely… (From ISO 31010): “it should be justifiable and appropriate to the situation or organization under consideration;” “it should provide results in a form which enhances understanding of the nature of the risk and how it can be treated;” “it should be capable of use in a manner that is traceable, repeatable and verifiable.”
  • 25. Risk Tool Selection (part 2) Consider: • the objectives of the study; • the needs of decision-makers; • the type and range of risks being analyzed; • the potential magnitude of the consequences; • the degree of expertise, human and other resources needed; • the availability of information and data; • the need for modification/updating of the risk assessment, and • any regulatory and contractual requirements.
  • 26. Risk assessment process Risk analysisTools and techniques Risk Identification Consequence Probability Level of risk Risk evaluation See Annex Brainstorming SA1) NA2) NA NA NA B 01 Structured or semi-structured interviews SA NA NA NA NA B 02 Delphi SA NA NA NA NA B 03 Check-lists SA NA NA NA NA B 04 Primary hazard analysis SA NA NA NA NA B 05 Hazard and operability studies (HAZOP) SA SA A3) A A B 06 Hazard Analysis and Critical Control Points (HACCP) SA SA NA NA SA B 07 Environmental risk assessment SA SA SA SA SA B 08 Structure « What if? » (SWIFT) SA SA SA SA SA B 09 Scenario analysis SA SA A A A B 10 Business impact analysis A SA A A A B 11 Root cause analysis NA SA SA SA SA B 12 Failure mode effect analysis SA SA SA SA SA B 13 Fault tree analysis A NA SA A A B 14 Event tree analysis A SA A A NA B 15 Cause and consequence analysis A SA SA A A B 16 Cause-and-effect analysis SA SA NA NA NA B 17 Layer protection analysis (LOPA) A SA A A NA B 18 Decision tree NA SA SA A A B 19 Human reliability analysis SA SA SA SA A B 20 Bow tie analysis NA A SA SA A B 21 Reliability centred maintenance SA SA SA SA SA B 22 Sneak circuit analysis A NA NA NA NA B 23 Markov analysis A SA NA NA NA B 24 Monte Carlo simulation NA NA NA NA SA B 25 Bayesian statistics and Bayes Nets NA SA NA NA SA B 26 FN curves A SA SA A SA B 27 Risk indices A SA SA A SA B 28 Consequence/probability matrix SA SA SA SA A B 29 Cost/benefit analysis A SA A A A B 30 Multi-criteria decision analysis (MCDA) A SA A SA A B 31 1) Strongly applicable. 2) Not applicable. 3) Applicable.
  • 27. Easy: Brainstorming Brainstorming involves stimulating and encouraging free-flowing conversation amongst a group of knowledgeable people to identify potential failure modes and associated hazards, risks, criteria for decisions and/or options for treatment. The term “brainstorming” is often used very loosely to mean any type of group discussion. However true brainstorming involves particular techniques to try to ensure that people's imagination is triggered by the thoughts and statements of others in the group.
  • 28. Easy: Structured Interviews In a structured interview, individual interviewees are asked a set of prepared questions from a prompting sheet which encourages the interviewee to view a situation from a different perspective and thus identify risks from that perspective. A semi-structured interview is similar, but allows more freedom for a conversation to explore issues which arise.
  • 29. Points of risk due to:  lack of criteria or planned execution  poor critical thinking skills  allowance for “fudging” aspects between activities  not knowing the level of risk
  • 30. November 30, 2016 30 Audit Team DEC 2016- DEC 2017 Month/Year Focusareas Planned Conducted Business Model Areas/ Function TopMgmt MRTeam* PdtPlanning QA QC Producment Suppliers ReceivingQC Chngecontrol In-ProcessQC ProdCC Label&Pkg Personnel Facilities Maintenance Comments (Part 11, 211, 820, etc. items) 4.1 Quality Mgmt System 13-Jan QM/ MR Minutes/ 4.2 Documentation 26-Dec Change control; format; Control 5.0 Management Responsibility 26-Dec Agendas; Participation; Actions 6.2 Resources Allocation 26-Dec QP/Job Desc's; Training; Responsibilities 6.3 Infrastructure 13-Jan Maintenance of facility to GMP/Changes/Events 6.4 Work Environment 27-Dec GMP application for hygiene, mfg, security, docs 7.1 Product/Process Planning 13-Feb Quality Plan, QM, Risk in IQA, Suppliers, Testing 7.2 Customer Requirements 13-Mar Review of Customer Specs/MMR development 7.3 Design & Development TBD Done by UAS. Auditing in 1Q 2013 with transfer 7.4 Purchasing 25-Jan Qualification of suppliers 7.5 Provision of Product 18-Dec MMRs to BMRs/review/approval 7.6 Calibration Capability 10-Jan By contract and in the field 8.2.1 M&M Customer 1Q Progress Reviews 8.2.2 Internal Audits 18-Dec Initially by contractor 8.2.3 M&M Processes 18-Dec Desktop for all processes, SOPs,Wis, Protocols 8.2.4 M&M Products 18-Dec BMRs/Logs/Reports, Raw Matl testing, CofAs 8.3 Control of Nonconformity 27-Dec NCR form and records 8.4 Analysis of Data 1Q Use data from NCRs 8.5.1 Continual Improvement 1Q Mgmt Review actions 8.5.2 Corrective Action 27-Dec Records of improvement actions 8.5.3 Preventive Action 28-Dec Records of improvement actions AUDIT PLAN/SCHEDULE PREPARED BY: (*MR = Management Review)Gopul K Tunga NOTES: 12/18/2016 Any IAFs generated to showing where improvements are identified in the process above and timeline Audit No. Audit Dates AUDIT ELEMENT & DESCRIPTION ISO 9001: 2000 & 21 CFR Part XXX Validation Activity for processes Accomplished with Internal Auditing
  • 32. PRACTICLE APPROACH FOR RISK (Product/Process/System)
  • 33. Case Study 2: Eyjafjallajökull What Risk Tools should be used? STOP! Do not pass go… Where’smystuff!?!?!?!?!?!
  • 34. The cloud of ash from the Icelandic volcano which has wreaked havoc on passengers and airports across Europe has also had significant global effects. The International Air Transport Association estimates that the ash crisis has led to the cancellation of hundreds of thousands of flights and cost the world's airlines many billions of dollars. Some airlines may not recover from the losses incurred. Risk is all about uncertainty or, more importantly, the effect of uncertainty on the achievement of objectives. On 15 November 2009, ISO published ISO 31000:2009, Risk Management – Principles and guidelines, to help industrial, commercial and public sector organizations to confidently address such risks.
  • 36. Summary Risk is here: get used to it •Mentioned 43x in the new update (vs 3x) •Risk-Based Thinking – it’s everywhere •It’s more than just risk: it’s opportunities •Use the correct tool for the job •And if nothing else: PS: DON’T RUN ELECTRICITY THROUGH A POOL
  • 37. ISO 9001 Training Course  ISO 9001 Introduction 1 Day Course  ISO 9001 Foundation 2 Days Course  ISO 9001 Lead Implementer 5 Days Course  ISO 9001 Lead Auditor 5 Days Course Exam and certification fees are included in the training price. https://www.pecb.com/iso-9001-training-courses| www.pecb.com/events